automation-recon-pipeline
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent for bug-bounty automation, but it gives an AI agent offensive recon/scanning capability and encourages unattended continuous execution. Install trust is mostly acceptable for official ProjectDiscovery tools, with moderate residual supply-chain risk from unpinned installs and the third-party `anew` utility. No clear credential harvesting or covert exfiltration is present.
Confidence: 89%Severity: 78%
Audit Metadata